---
id: CVE-2026-15206
title: >-
  The SMS Alert  WordPress plugin before 3.9.8 does not bind its "mobile
  verified" session flag to the phone number that was actually verified: after
  an attacker verifies an OTP sent to their own phone, the signup/login handler
  reads a fre…
summary: >-
  The SMS Alert  WordPress plugin before 3.9.8 does not bind its "mobile
  verified" session flag to the phone number that was actually verified: after
  an attacker verifies an OTP sent to their own phone, the signup/login handler
  reads a fre…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15206'
references:
  - url: 'https://wpscan.com/vulnerability/d0bb4c41-392a-4209-9e44-93dbf3898417/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T13:18:29.033Z'
epss: 0.00406
epssPercentile: 0.32305
---

## Overview

The SMS Alert  WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
